Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,10 @@ Optional. Do not install yarn. If set to `true`, yarn must be available in the e

Optional. The directory from which to look for and run `yarn audit`. Default `.`.

### `yarn_audit_flags`

Optional. Yarn audit flags. (`yarn audit --json <yarn_audit_flags>`).

## Example usage

```yaml
Expand All @@ -86,6 +90,7 @@ jobs:
uses: codeur/action-yarn-audit@v0
with:
reporter: github-pr-review
yarn_audit_flags: --level moderate
```

## Dev
Expand All @@ -105,7 +110,7 @@ jobs:
You can test locally with a command like that:

```sh
GITHUB_WORKSPACE=$(pwd) INPUT_WORKDIR=test/rdjson_formatter/testdata INPUT_TOOL_NAME="yarn audit" INPUT_LEVEL=error INPUT_FAIL_LEVEL=any INPUT_REPORTER=local GITHUB_ACTION_PATH=$(pwd) ./script.sh
GITHUB_WORKSPACE=$(pwd) INPUT_WORKDIR=test/rdjson_formatter/testdata INPUT_TOOL_NAME="yarn audit" INPUT_LEVEL=error INPUT_FAIL_LEVEL=any INPUT_REPORTER=local INPUT_YARN_AUDIT_FLAGS="--level moderate" GITHUB_ACTION_PATH=$(pwd) ./script.sh
```

## License
Expand Down
4 changes: 4 additions & 0 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,9 @@ inputs:
workdir:
description: "The directory from which to look for and run yarn audit. Default '.'"
default: '.'
yarn_audit_flags:
description: 'Yarn audit flags. (yarn audit --json <yarn_audit_flags>)'
default: ''
runs:
using: 'composite'
steps:
Expand All @@ -56,6 +59,7 @@ runs:
INPUT_SKIP_INSTALL: ${{ inputs.skip_install }}
INPUT_TOOL_NAME: ${{ inputs.tool_name }}
INPUT_WORKDIR: ${{ inputs.workdir }}
INPUT_YARN_AUDIT_FLAGS: ${{ inputs.yarn_audit_flags }}
branding:
icon: 'check-circle'
color: 'red'
2 changes: 1 addition & 1 deletion script.sh
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ echo "::group:: Running yarn audit with reviewdog 🐶..."
# NOTE: yarn audit exits with non-zero code when vulnerabilities are found,
# so we suppress its exit code to let reviewdog determine the final result.
# shellcheck disable=SC2086
(yarn audit --json || true) \
(yarn audit --json ${INPUT_YARN_AUDIT_FLAGS} || true) \
| ruby "${GITHUB_ACTION_PATH}/rdjson_formatter/rdjson_formatter.rb" \
| reviewdog -f=rdjson \
-name="${INPUT_TOOL_NAME}" \
Expand Down